Total
100
Critical
3
High
79
Medium
18
CISA KEV
1
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
Memory corruption while using alignments for memory allocation.
Memory Corruption when adding user-supplied data without checking available buffer space.
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Information disclosure while processing a firmware event.
Transient DOS while parsing video packets received from the video firmware.
Memory corruption while processing MFC channel configuration during music playback.
Information disclosure while registering commands from clients with diag through diagHal.
Memory corruption during PlayReady APP usecase while processing TA commands.
Transient DOS while parsing the EPTM test control message to get the test pattern.
Cryptographic issue while performing RSA PKCS padding decoding.
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
Memory corruption while processing data packets in diag received from Unix clients.
Memory corruption while processing video packets received from video firmware.
Memory corruption may occur while processing voice call registration with user.
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
Memory corruption while reading the FW response from the shared queue.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Memory corruption while sound model registration for voice activation with audio kernel driver.
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
Memory corruption while calling the NPU driver APIs concurrently.
Transient DOS may occur while processing the country IE.
Memory corruption may occur while validating ports and channels in Audio driver.
While processing the authentication message in UE, improper authentication may lead to information disclosure.
Information disclosure while parsing the OCI IE with invalid length.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption while processing GPU page table switch.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
Memory corruption while handling session errors from firmware.
Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.
Transient DOS while parsing ESP IE from beacon/probe response frame.
Information disclosure while parsing the multiple MBSSID IEs from the beacon.
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
Memory corruption while processing IOCTL call for getting group info.
Memory corruption when two threads try to map and unmap a single node simultaneously.
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
Memory corruption while allocating memory in HGSL driver.
Memory corruption while processing IOCTL call to set metainfo.
Transient DOS while parsing ESP IE from beacon/probe response frame.
Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
Memory corruption when allocating and accessing an entry in an SMEM partition.
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
Memory corruption when the payload received from firmware is not as per the expected protocol size.
Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.
Memory corruption when there is failed unmap operation in GPU.
Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem.
Memory corruption while invoking IOCTLs calls in Automotive Multimedia.
Memory corruption while invoking HGSL IOCTL context create.
Memory corruption in Audio while processing RT proxy port register driver.
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
Memory corruption in Audio while processing the calibration data returned from ACDB loader.
Memory corruption in Audio while processing IIR config data from AFE calibration block.
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.
Transient DOS in Audio when invoking callback function of ASM driver.
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
Memory corruption in Audio when memory map command is executed consecutively in ADSP.
Memory corruption in Audio during playback with speaker protection.
Memory corruption in HLOS while running playready use-case.
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
Memory corruption while using the UIM diag command to get the operators name.
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
Memory corruption in Audio while processing the VOC packet data from ADSP.
Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.
Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.
Memory corruption while processing audio effects.
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE.
Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE.
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
Memory corruption in Audio during playback session with audio effects enabled.
Transient DOS in Audio while remapping channel buffer in media codec decoding.
Memory corruption while allocating memory in COmxApeDec module in Audio.
Memory Corruption in Audio while playing amrwbplus clips with modified content.
Memory corruption in WLAN while running doDriverCmd for an unspecific command.